NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87369  CVE-2017-2841  An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary data in the msmtprc configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.    6.5  Medium  2017-07-18  2017-07-05  View
87370  CVE-2017-2842  In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the msmtprc configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.    6.5  Medium  2017-07-18  2017-07-05  View
87632  CVE-2017-10672  Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.    7.5  High  2017-07-18  2017-07-05  View
87635  CVE-2017-10678  Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.    6.8  Medium  2017-07-18  2017-07-05  View
87636  CVE-2017-10679  Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.    Medium  2017-07-18  2017-07-05  View

Page 1306 of 17672, showing 5 records out of 88360 total, starting on record 6526, ending on 6530

Actions